fix(scan): record baselined findings in scan output - #338
Closed
vibgrate-team wants to merge 1 commit into
Closed
vibgrate-team wants to merge 1 commit into
vibgrate-team wants to merge 1 commit into
Conversation
vg scan --baseline previously kept only a numeric drift delta, so matched findings left no auditable trace in JSON or SARIF. The artifact now includes baselineComparison (compared, suppressedCount, and suppressed sorted by ruleId, location, then id). Findings stay in the primary array, human reports include the count, and SARIF suppressions carry the same ids. Fixes #161 Signed-off-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vg scan --baselinecompared a saved baseline only to compute a numeric drift delta (and to drive--drift-worsening). Matched findings were not recorded anywhere in the machine-readable artifact, so a baseline looked like a silent drop.The scan artifact now keeps every finding in
findingsand adds an auditablebaselineComparisonblock when a baseline file is read:suppressedis sorted byruleId, thenlocation, thenid.idis 32 lowercase hex characters from the finding's rule, level, location, and message. The same finding always produces the same id; a changed message does not match.baselinestring (the compared file path) is unchanged, so the schema addition is version-safe. The comparison record is the new object rather than a replacement for that string.Baseline suppressions: Nand mark matched rows(baselined).suppressionsentry whoseproperties.idis the same id. Unmatched results have nosuppressionsfield.Related issues
Fixes #161
Checklist
pnpm testpassespnpm lintis cleanpnpm typecheckis cleangraph.json/ report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)git commit -s, DCO)Notes for reviewers
Verify with the fixture in
test/fixtures/baseline-suppressions.json(no credentials) and:pnpm exec vitest run test/baseline-comparison.test.ts src/reporting/formatters/formatters.test.ts vg baseline vg scan --baseline .vibgrate/baseline.json --format jsonThe JSON artifact should contain
baselineComparisonalongside the fullfindingsarray.--format sarifshould repeat those ids undersuppressions, and the text report should include the count.